There is no single certificate that makes a business automatically “approved to work with schools”.
School supplier compliance is usually a collection of legal duties, business controls, policies, evidence and practical arrangements that depend on what the supplier provides.
A company delivering exercise books has a very different risk profile from an EdTech platform processing pupil data. A building contractor working during the school day needs different documentation from an online training provider. A counsellor meeting pupils individually will face more extensive safeguarding questions than a furniture manufacturer delivering goods to reception.
This is why generic claims such as “fully school compliant” are rarely useful. A supplier must understand which requirements apply to its organisation, employees, subcontractors, product and method of delivery.
Schools and academy trusts may ask for evidence covering:
- the supplier’s legal identity;
- insurance;
- safeguarding;
- DBS-checking arrangements;
- health and safety;
- risk assessments;
- data protection;
- cybersecurity;
- accessibility;
- financial standing;
- references;
- contract terms;
- business continuity;
- subcontractors;
- quality and service controls.
Not every school will request every document, and not every document will be relevant to every supplier. The purpose of a compliance checklist is not to produce the largest possible folder. It is to make sure the supplier can show that it has identified and managed the actual risks created by its work.
This guide provides a practical school supplier compliance checklist for businesses working with schools and multi-academy trusts in England. It is designed to help suppliers prepare for due diligence, identify missing information and avoid making inaccurate claims about DBS checks, safeguarding, insurance or data protection.
Begin with the supplier’s legal and business information
Before a school assesses safeguarding, service quality or technical security, it needs to know which organisation it may be contracting with.
This sounds basic, but supplier identities are often unclear.
A business may trade under a brand that differs from its registered company name. A group of related companies may use one website but invoice through another entity. A consultant may present themselves as a company while legally operating as a sole trader. A sales proposal may name one organisation, while the contract and bank account belong to another.
This creates unnecessary concern for finance and procurement teams.
Your core business-information record should include:
- full legal name;
- trading name, where different;
- business structure;
- company number, where applicable;
- registered office;
- principal trading address;
- VAT number, where applicable;
- website;
- main telephone number;
- finance and procurement contact;
- contract contact;
- bank details supplied through a secure process;
- details of any parent company or guarantor relevant to the contract.
A UK limited company should display specified company information on its website and business correspondence, including its registered company name, company number, registered office and place of registration. Suppliers should check the current GOV.UK guidance on company information and business stationery.
Use the same legal identity consistently across:
- the website;
- sales pack;
- quotation;
- supplier-onboarding form;
- contract;
- purchase order;
- invoice;
- insurance documents;
- data-processing agreement.
Where different entities perform different roles, explain them.
For example:
“ABC Education is the trading name of ABC Learning Services Ltd, which will enter the contract and issue invoices. Hosting is provided by XYZ Cloud Ltd as a subprocessor.”
Schools may also ask for evidence of financial or operational stability, particularly for high-value, long-term or business-critical contracts.
Depending on the opportunity, this may include:
- recent accounts;
- credit information;
- bank references;
- turnover information;
- details of significant litigation;
- business-continuity arrangements;
- confirmation that taxes and statutory filings are up to date;
- parent-company guarantees;
- performance bonds for substantial projects.
A small supplier should not assume that limited company size prevents it from working with schools. It should, however, be ready to explain how the service will continue during staff absence, illness, technical failure or rapid customer growth.
A clear legal and business profile is the foundation of the wider assurance pack described in What to Include in a School Supplier Sales Pack.
Arrange insurance that matches the work being performed
There is no universal insurance package suitable for every school supplier.
The required policies and levels of cover depend on the work, contract, business structure and risks involved. A school or trust may also specify minimum insurance requirements in a tender or contract.
Common policies include the following.
Public liability insurance
Public liability insurance can cover claims arising from injury to third parties or damage to their property caused by the supplier’s activities.
It is particularly relevant where suppliers:
- visit school sites;
- deliver activities;
- install equipment;
- work around pupils, staff or visitors;
- provide maintenance or construction services;
- bring equipment onto the premises.
Schools commonly ask for evidence of public liability cover, although the required level varies. Do not assume that one figure applies to every contract.
Employers’ liability insurance
Most employers are legally required to hold employers’ liability insurance. It covers claims from employees who become injured or ill because of their work.
The certificate should be current and should name the correct employing entity.
Professional indemnity insurance
Professional indemnity insurance may be relevant where the supplier provides advice, designs, assessments, consultancy, specialist reports or professional services.
Examples include:
- education consultancy;
- legal or HR advice;
- architectural or engineering work;
- educational psychology;
- IT consultancy;
- school improvement support;
- design and specification services.
Product liability insurance
This may be relevant to suppliers that manufacture, import, distribute or sell physical products. It can address claims arising from injury or damage caused by a defective product.
Cyber insurance
Cyber cover may be relevant for software companies, managed IT providers and businesses holding significant amounts of personal or confidential data. It should support, rather than replace, appropriate security controls.
Other specialist cover
Depending on the service, suppliers may need to consider:
- medical malpractice or treatment liability;
- abuse or molestation cover;
- motor and hired-in vehicle insurance;
- contract works insurance;
- plant and equipment cover;
- environmental liability;
- business interruption;
- personal accident cover;
- legal expenses;
- professional registrations with associated indemnity arrangements.
Review policy exclusions carefully.
A certificate showing a large coverage amount does not prove that the relevant activity is insured. The insurer may exclude work involving children, particular treatments, certain sports, high-risk activities, professional advice, cyber incidents or subcontractors.
Suppliers should be able to provide:
- the current certificate;
- the insured entity;
- policy number;
- coverage period;
- indemnity limit;
- relevant territorial limits;
- confirmation that the declared business activities include the proposed work;
- details of material exclusions where relevant.
Do not state that a school “requires £10 million public liability insurance” as a universal rule. A particular school, local authority, framework or trust may specify that amount, but another contract may use a different requirement.
Ask what cover the buyer requires and confirm it with your broker or insurer before agreeing to the contract.
Put safeguarding arrangements in place before working with pupils
Safeguarding is broader than obtaining DBS certificates.
A supplier that works with children should be able to explain how it recruits staff, manages conduct, responds to concerns, works with the school’s designated safeguarding lead and controls the risks created by its activity.
The current statutory Keeping Children Safe in Education guidance sets out the legal duties schools and colleges must follow to safeguard and promote the welfare of children. Although it is primarily addressed to schools and colleges, external providers need to understand the safeguarding environment in which schools operate.
A supplier safeguarding framework may include:
- a safeguarding and child-protection policy;
- a named safeguarding lead;
- clear reporting and escalation procedures;
- a code of conduct for staff and contractors;
- safer-recruitment procedures;
- appropriate references and identity checks;
- role-based DBS eligibility assessment;
- safeguarding induction and training;
- rules for one-to-one work;
- supervision arrangements;
- online-safety procedures;
- photography and recording rules;
- guidance on physical contact;
- procedures for allegations involving supplier staff;
- whistleblowing arrangements;
- record-keeping and information-sharing controls;
- arrangements for subcontractors and temporary staff.
The policy must reflect what the business actually does.
A generic policy copied from another organisation may refer to job roles, referral routes or procedures that do not exist in the supplier’s business. This can be worse than having a shorter, carefully written policy because it creates false assurance.
Before delivery, agree practical arrangements with the school:
- who the school’s designated safeguarding lead is;
- how supplier staff report an immediate concern;
- what to do if the concern relates to a member of school staff;
- which areas supplier staff may access;
- whether they will be supervised;
- whether they may work one-to-one with pupils;
- how attendance is recorded;
- how pupil information is shared;
- what happens during emergencies;
- which school policies must be followed.
Supplier staff should know that they must report concerns through the agreed route rather than investigate them personally.
For activities involving remote contact, online tutoring, mentoring or digital communication, the supplier should address:
- approved communication platforms;
- personal phone numbers and accounts;
- recording of sessions;
- parent or school involvement;
- one-to-one visibility and supervision;
- inappropriate contact outside scheduled sessions;
- the storage of messages and recordings;
- the procedure for raising concerns.
Schools may ask for a letter of assurance confirming that the provider has completed specified checks. Only give assurances that are accurate and supported by records.
A safeguarding policy is not a marketing badge. It is an operational system that staff must understand and use.
Assess DBS eligibility role by role rather than making blanket claims
One of the most common school supplier compliance mistakes is assuming that every person entering a school needs the same DBS check.
The opposite mistake is assuming that no check is needed because supplier staff are not employed by the school.
DBS eligibility depends on the role, activity, setting, frequency, supervision and legal rules applying to the work.
The Disclosure and Barring Service explains that Standard, Enhanced and Enhanced checks with barred-list information are available only where the law permits the employer or organisation to ask the relevant exempted question. Suppliers cannot request higher-level checks simply because they would be reassuring.
Where a person carries out regulated activity with children in England or Wales, an Enhanced DBS check including a Children’s Barred List check may be available. The DBS publishes current guidance on regulated activity with children.
The supplier should complete a role-based assessment covering:
- the activity being performed;
- whether it involves teaching, training, care, supervision, advice or treatment;
- the age of the children;
- the frequency of the work;
- whether the person will be supervised;
- whether the activity occurs in a specified establishment;
- whether barred-list information is legally available;
- which organisation is responsible for requesting or checking the disclosure.
Different people within one supplier may need different arrangements.
For example:
- a tutor working regularly and unsupervised with pupils;
- an engineer repairing equipment in a locked plant room;
- a delivery driver leaving boxes at reception;
- a photographer working under direct school supervision;
- a counsellor providing confidential one-to-one support;
- an office-based administrator with access to pupil data but no contact with children.
These roles should not automatically be treated as identical.
A supplier should keep appropriate records of:
- the role assessed;
- the reason a particular check was considered eligible;
- the disclosure level;
- the date checked;
- identity verification;
- who reviewed the result;
- the recruitment decision;
- any risk assessment required;
- ongoing or update-service arrangements where used.
Handle DBS information securely. Do not circulate full certificates to multiple schools unless there is a lawful and necessary reason to do so.
A useful assurance statement is specific:
“Staff assigned to pupil-facing roles are assessed individually for DBS eligibility. Where the role is regulated activity, we obtain the appropriate Enhanced DBS check with Children’s Barred List information before deployment. We provide schools with written confirmation of the relevant checks and recruitment controls.”
Avoid phrases such as:
- “DBS approved”;
- “fully DBS certified”;
- “all employees have the highest DBS check”;
- “a DBS check proves the individual is safe”;
- “the school does not need to carry out any further safeguarding checks”.
A DBS check is one element of safer recruitment and ongoing safeguarding. It is not a guarantee of suitability.
Manage health and safety according to the actual activity
Suppliers are responsible for protecting their employees and other people who may be affected by their work.
HSE guidance states that employers must identify hazards, assess risks and take action to eliminate or control them. A suitable and sufficient risk assessment is a legal requirement, and significant findings generally need to be recorded where the employer has five or more employees.
The school also has responsibilities for its premises, employees, pupils and visitors. Safe delivery therefore depends on cooperation and the exchange of relevant information.
The HSE’s guidance on using contractors emphasises defining the work, selecting competent contractors, assessing risks, providing information and coordinating activities.
Your health and safety documentation may include:
- health and safety policy;
- general risk assessment;
- activity-specific risk assessments;
- site-specific risk assessment;
- method statements;
- COSHH assessments;
- manual-handling assessments;
- work-at-height arrangements;
- equipment inspection and maintenance records;
- electrical safety records;
- vehicle and driver controls;
- first-aid arrangements;
- accident and incident reporting;
- emergency procedures;
- staff competence and training records;
- personal protective equipment requirements;
- subcontractor controls.
The documents required should match the work.
A science workshop using chemicals or heat may need detailed controls for substances, equipment, supervision and emergency response.
A furniture installation may need to address delivery vehicles, manual handling, tools, room access, pupils nearby, packaging and waste removal.
A building contractor may need construction-phase arrangements, site segregation, asbestos information, permits, work-at-height controls and compliance with the Construction (Design and Management) Regulations where applicable.
A wellbeing provider delivering seated staff training may need a much simpler assessment, but should still consider the venue, emergency procedures and any activity-specific risks.
Before arriving, ask the school for relevant site information, including:
- sign-in and identification procedures;
- fire and evacuation arrangements;
- restricted areas;
- asbestos or site hazard information relevant to the work;
- vehicle and delivery restrictions;
- working hours;
- supervision arrangements;
- first-aid contacts;
- how work will be separated from pupils;
- the process for reporting incidents.
Risk assessments should be living documents rather than forms completed once and forgotten. Government guidance for schools similarly describes risk assessments as documents that must be reviewed and updated as circumstances change.
Review your assessment when:
- the activity changes;
- the site differs materially;
- new equipment or substances are introduced;
- an incident or near miss occurs;
- the needs of participants change;
- the school identifies a new hazard;
- the existing controls prove ineffective.
Do not send the same generic risk assessment to every school when the site or activity requires specific consideration.
Prepare data protection and cybersecurity evidence where personal data is involved
Data protection requirements apply when a supplier collects, accesses, stores, uses, shares or otherwise processes personal data.
School-related data can include:
- pupil names and identifiers;
- attendance;
- assessment information;
- SEND information;
- health details;
- safeguarding information;
- parent and carer details;
- staff records;
- images, recordings and voice data;
- online identifiers;
- usage and behavioural data.
Begin by determining whether the supplier acts as a controller, processor or joint controller for each activity.
The Information Commissioner’s Office explains that controllers decide the purposes and means of processing, while processors handle personal data on the controller’s documented instructions. The correct role depends on the reality of the arrangement, not merely the label used in a contract.
Where a school acts as controller and uses the supplier as processor, a written contract containing the required UK GDPR provisions must be in place. The ICO explains that controller–processor contracts clarify the parties’ obligations, responsibilities and liabilities.
A school supplier data-protection pack may include:
- privacy notice;
- record of processing activities;
- controller–processor assessment;
- data-processing agreement;
- data-flow map;
- list of subprocessors;
- hosting locations;
- international-transfer arrangements;
- retention schedule;
- data-deletion process;
- subject-rights procedure;
- breach-response process;
- information-security policy;
- access-control policy;
- business-continuity and disaster-recovery arrangements;
- penetration-testing or vulnerability-management information;
- relevant certifications or independent assessments;
- contact details for data and security questions.
The processor contract should address the required matters, including:
- subject matter and duration;
- nature and purpose of processing;
- types of personal data;
- categories of data subject;
- controller rights and obligations;
- documented instructions;
- confidentiality;
- security measures;
- subprocessors;
- support for data-subject rights;
- assistance with breaches and impact assessments;
- data return or deletion;
- audit information.
The ICO notes that subprocessors must be subject to equivalent data-protection obligations through an appropriate contract.
For EdTech, be especially clear about:
- whether data is used for advertising;
- whether data trains or improves commercial AI systems;
- which analytics are collected;
- whether pupil profiles are created;
- whether data is shared outside the core service;
- how accounts are created and removed;
- how schools obtain their data when leaving;
- what happens when pupils move school;
- how long backups retain deleted information.
The ICO has emphasised that children may have little practical ability to opt out of technology selected by their school, making responsible and fair processing particularly important for EdTech products.
Cybersecurity documentation should be accurate rather than promotional.
Avoid saying:
- “100% secure”;
- “fully GDPR certified”;
- “military-grade security” without explanation;
- “data never leaves the UK” when foreign subprocessors or support access are involved;
- “we do not process personal data” merely because the school uploads it.
Explain controls such as:
- encryption in transit and at rest;
- multi-factor authentication;
- role-based access;
- logging and monitoring;
- backup and recovery;
- patching;
- vulnerability management;
- staff security training;
- incident detection;
- breach notification;
- independent testing.
Security measures should be proportionate to the sensitivity, volume and use of the data.
Check product safety, accessibility and sector-specific requirements
General compliance documents are not enough when the product or service falls within a regulated or specialist area.
Suppliers should identify all product-specific requirements before marketing to schools.
Physical products
Depending on the product, consider:
- applicable product-safety law;
- conformity marking;
- testing and technical files;
- manufacturer and importer responsibilities;
- age suitability;
- instructions and warnings;
- flammability;
- chemical content;
- load limits;
- electrical safety;
- warranties;
- recall procedures;
- spare parts and maintenance.
Do not describe a product as compliant with a standard unless you can identify the applicable standard, test method, version and evidence.
Food and catering
Suppliers may need to address:
- food-business registration;
- food hygiene;
- allergen management;
- temperature control;
- traceability;
- staff training;
- school food standards where applicable;
- delivery and storage;
- incident and recall procedures.
Transport
Transport providers may need evidence concerning:
- operator licensing;
- vehicle licensing and maintenance;
- driver eligibility;
- insurance;
- seat belts and accessibility;
- passenger supervision;
- emergency procedures;
- journey risk assessment.
Clinical, therapeutic and specialist services
Where applicable, check:
- professional registration;
- scope of practice;
- clinical governance;
- consent;
- record keeping;
- professional indemnity;
- supervision;
- complaints;
- referral and escalation;
- information sharing.
Construction and premises work
Relevant matters may include:
- CDM duties;
- trade competence;
- gas, electrical or other registrations;
- asbestos awareness;
- permits to work;
- construction-phase planning;
- waste carriage;
- building regulations;
- fire safety;
- site protection.
Digital accessibility
Digital suppliers should assess whether websites, apps, documents and learning platforms can be used by disabled pupils, staff and parents.
Schools and other public-sector bodies may need to meet accessibility requirements for websites and mobile applications. Government guidance encourages schools to discuss accessibility requirements and accessibility statements with their digital suppliers.
A digital assurance pack may include:
- an accessibility statement;
- the standard or guidelines used for testing;
- testing methodology;
- known limitations;
- reasonable workaround information;
- the process for reporting problems;
- the remediation roadmap.
Avoid saying that a platform is “fully accessible” unless the statement is supported by rigorous testing and appropriately qualified. Accessibility is an ongoing responsibility, especially as software changes.
Intellectual property and licensing
Teaching resources, assessments, photographs, music, video and software may involve copyright, trademarks, database rights and licences.
Suppliers should be able to explain:
- what the school is licensed to use;
- which staff and pupils are covered;
- whether materials can be copied or adapted;
- whether access continues after the contract;
- whether third-party content is properly licensed;
- how school-created content is treated;
- who owns commissioned work.
Do not assume that buying a resource automatically permits unlimited copying across a MAT.
Use fair, clear contracts and procurement information
Compliance continues into the commercial agreement.
A school should be able to understand the commitment it is entering and the remedies available if the supplier fails to deliver.
Standard terms should address:
- correct legal parties;
- scope;
- price;
- payment;
- contract period;
- service levels;
- school and supplier responsibilities;
- insurance;
- confidentiality;
- data protection;
- safeguarding where relevant;
- intellectual property;
- subcontracting;
- liability;
- termination;
- renewal;
- business continuity;
- dispute resolution;
- exit and handover.
Contract wording should match the proposal and sales conversation.
A school may reasonably object where:
- a one-year proposal becomes a three-year contract;
- renewal is automatic but was not disclosed;
- the supplier can increase prices without limits;
- service levels are omitted;
- liability is excluded almost entirely;
- the supplier can suspend a critical service immediately;
- school data cannot be exported on termination;
- the contract permits unrestricted subcontracting;
- the school is charged to retrieve its own information.
Academy trusts and maintained schools operate financial and governance controls over public funds. The current Academy Trust Handbook sets the financial-management framework applying to academy trusts, while maintained schools operate through local-authority schemes and governing-body controls.
Suppliers should therefore be ready to explain:
- the procurement route;
- framework membership, where relevant;
- the exact framework lot and reference;
- whether direct award or further competition applies;
- contract value over its full term;
- renewal and extension options;
- all implementation and support costs;
- social-value commitments made in a tender;
- conflicts of interest;
- related-party relationships.
Do not claim that inclusion on a framework makes the business universally “approved by the Department for Education”. Explain the precise framework and how the school can use it.
Suppliers should also declare actual or potential conflicts of interest. This is particularly important where:
- the supplier is connected to a trustee, governor or employee;
- a consultant advising the school also benefits from the purchase;
- the supplier helped write the specification;
- gifts, hospitality or referral payments are involved;
- the transaction is with a related party.
Academy trusts are subject to specific requirements concerning conflicts and related-party transactions. The government publishes current guidance on identifying, managing and reporting these arrangements.
A supplier should never encourage a school contact to bypass procurement, split orders artificially or misstate the value of a contract.
Build a compliance pack that remains current
A compliance pack is valuable only when its contents are accurate.
Policies copied into a folder and forgotten can become a liability. Insurance expires. Staff change. Subprocessors are replaced. Contract terms are revised. New services create new risks.
Create a controlled assurance register.
| Document or control | Owner | Review or expiry | Status |
|---|---|---|---|
| Public liability certificate | Operations director | 31 March 2027 | Current |
| Safeguarding policy | Safeguarding lead | January 2027 | Current |
| DBS role assessments | HR | When roles change | Review required for new role |
| Data-processing agreement | Data protection lead | October 2026 | Current |
| Subprocessor register | Security lead | Quarterly | Current |
| Standard school contract | Commercial director | December 2026 | Under review |
Assign a named owner for each area:
- legal and company information;
- insurance;
- safeguarding;
- DBS and recruitment;
- health and safety;
- data protection;
- cybersecurity;
- accessibility;
- contracts;
- finance;
- subcontractors;
- quality and complaints.
Your core pack might contain:
Corporate folder
- company details;
- tax and VAT information;
- bank-verification process;
- accounts or financial evidence where required;
- business-continuity summary.
Insurance folder
- current certificates;
- coverage summary;
- broker contact;
- relevant endorsements.
Safeguarding and people folder
- safeguarding policy;
- code of conduct;
- safer-recruitment process;
- DBS role assessment;
- training record;
- letter-of-assurance template;
- allegations and escalation procedure.
Health and safety folder
- policy;
- risk-assessment templates;
- activity assessments;
- method statements;
- competence and training records;
- incident procedure.
Data and security folder
- privacy notice;
- data-processing agreement;
- data-flow information;
- subprocessor register;
- security controls;
- incident-response process;
- retention and deletion schedule;
- accessibility statement.
Commercial folder
- standard terms;
- service levels;
- pricing schedule;
- framework information;
- conflict-of-interest declaration;
- complaints procedure;
- exit plan.
Use clear filenames and dates:
Public-Liability-Insurance-Expires-2027-03-31.pdfSafeguarding-Policy-Version-4-January-2026.pdfData-Processing-Agreement-Version-3-2.pdfSchool-Supplier-Terms-Version-5.pdf
Do not place confidential personal information, full DBS certificates, unredacted security tests or sensitive employee records inside a general download folder.
Create different access levels:
- public website information;
- sales-stage assurance summary;
- due-diligence documents;
- confidential material shared securely under appropriate controls.
Review the whole compliance pack whenever:
- a new product launches;
- the supplier begins working directly with pupils;
- a new category of personal data is processed;
- delivery moves into a new country;
- a subprocessor changes;
- a subcontractor is appointed;
- insurance renews;
- a relevant law or official guidance changes;
- an incident exposes a weakness;
- a school repeatedly asks a question the pack does not answer.
School supplier compliance checklist
Use this checklist as a starting point. Mark items as:
- required and complete;
- required but missing;
- under review;
- not applicable, with a recorded reason.
Business identity
- Legal entity confirmed
- Trading name linked clearly to legal entity
- Company details displayed correctly
- VAT position confirmed
- Quotation, contract and invoice identities aligned
- Finance and contract contacts identified
- Bank-detail change procedure established
- Financial-standing evidence available where needed
- Business-continuity arrangements documented
Insurance
- Public liability reviewed
- Employers’ liability in place where legally required
- Professional indemnity considered
- Product liability considered
- Cyber insurance considered
- Specialist cover reviewed
- Declared activities match school services
- Material exclusions checked
- Certificates current
- Renewal owner and reminder set
Safeguarding
- Safeguarding policy reflects actual work
- Named safeguarding lead
- Reporting and escalation process
- Code of conduct
- Safer-recruitment procedure
- Reference and identity checks
- Safeguarding induction and training
- One-to-one working arrangements
- Online communication controls
- Photography and recording procedure
- Allegations procedure
- Whistleblowing route
- Subcontractor safeguarding controls
- School-specific briefing before delivery
DBS
- Each role assessed for legal eligibility
- Regulated-activity assessment documented
- Correct check level requested
- Barred-list information requested only where legally permitted
- Identity verification completed
- Secure record-keeping process
- Decision process for disclosed information
- Update-service arrangements defined where used
- School assurance letter accurate
- No misleading “DBS approved” claims
Health and safety
- Health and safety policy
- General risk assessment
- Activity-specific risk assessment
- Site-specific review where required
- Method statements
- COSHH assessments where applicable
- Equipment checks and maintenance
- Staff competence and training
- First-aid arrangements
- Incident and near-miss process
- Emergency arrangements
- Vehicle and delivery controls
- Subcontractor controls
- Review process after change or incident
Data protection and cyber security
- Controller and processor roles assessed
- Privacy notice
- Data-processing agreement
- Data categories documented
- Lawful processing responsibilities understood
- Data-flow map
- Subprocessor register
- Hosting and transfer locations documented
- Security controls documented
- Access management
- Retention and deletion schedule
- Data return and contract-exit process
- Incident-response and breach-notification process
- Backup and disaster recovery
- Staff security training
- Testing and vulnerability management
- School security questionnaire process
Products and specialist services
- Applicable product-safety law identified
- Conformity and testing evidence
- Instructions and warnings
- Age and setting suitability
- Professional registrations current
- Specialist licences and permits
- Food, transport or clinical requirements assessed
- Construction and trade competence verified
- Accessibility reviewed
- Intellectual-property and licensing rights confirmed
- Product recall or service incident procedure
Contracts and procurement
- Correct contracting party
- Clear scope
- Complete price
- VAT and additional costs disclosed
- Contract period
- Renewal and notice terms
- Service levels
- Data and safeguarding clauses where relevant
- Subcontracting terms
- Liability and insurance aligned
- Termination and exit process
- Framework claims verified
- Conflicts declared
- Related-party relationships disclosed
- Purchase-order and invoicing process supported
Ongoing assurance
- Document register
- Named owners
- Review and expiry dates
- Version control
- Staff training records
- Complaints log
- Incident log
- Corrective-action process
- Customer references reviewed
- Subcontractors rechecked
- Website claims checked against evidence
- Annual full compliance review
A checklist should record evidence, not simply yes-or-no answers.
For example:
Public liability: £5 million cover with Example Insurer, policy PL12345, expires 31 March 2027. Broker has confirmed that school workshop activities are included.
This is more useful than:
Insurance: Yes.
Frequently asked questions
Is there an official school supplier compliance certificate?
No general certificate makes a business automatically compliant or approved to supply every UK school. Requirements depend on the product, activity, contract, risk and school’s own due-diligence process.
Does every school supplier need a DBS check?
No. DBS eligibility depends on the individual’s role and activity. Some pupil-facing roles may qualify for an Enhanced check with Children’s Barred List information, while other contractors may not be eligible for that level of check. Each role should be assessed separately.
Does every person entering a school need an Enhanced DBS check?
No. Entry to a school site does not automatically create eligibility for an Enhanced DBS check. The nature, frequency and supervision of the activity matter. Schools may use other controls for visitors and contractors whose roles do not qualify.
Does a DBS check prove someone is safe to work with children?
No. It provides criminal-record and, where legally permitted, barred-list information at a particular point or through an update arrangement. Safer recruitment also includes identity, references, employment history, suitability assessment, supervision, conduct and safeguarding procedures.
What insurance do school suppliers need?
It depends on the work. Common policies include public liability, employers’ liability, professional indemnity and product liability. Specialist services may require additional cover. The supplier should confirm that the insured business activities and exclusions match the proposed school work.
How much public liability insurance do schools require?
There is no single amount required by every school. The required limit may be set by the school, local authority, MAT, framework or contract and will depend on the risk. Suppliers should ask for the specific requirement and confirm cover with their broker.
Does a supplier need a safeguarding policy?
A supplier working directly with children should have safeguarding arrangements appropriate to its activity, normally including a policy, named lead, reporting process, staff conduct requirements, safer recruitment and training. Suppliers with no pupil contact may need a more limited approach but must still understand site and reporting procedures.
Does a software supplier need a data-processing agreement?
Where the supplier processes personal data on the school’s behalf, a written controller–processor contract containing the required UK GDPR terms is necessary. The exact arrangement depends on whether the supplier is a processor, controller or joint controller for each activity.
Is a privacy policy enough for an EdTech supplier?
No. A public privacy notice explains processing to individuals, but the school may also need a data-processing agreement, security information, subprocessor list, data-flow details, retention rules and exit arrangements.
Can a supplier say it is GDPR certified?
Only where the statement refers accurately to a recognised certification and its scope. UK GDPR compliance is not established simply by displaying a badge or writing a privacy policy. Avoid broad claims that cannot be substantiated.
What should be included in a school supplier assurance pack?
It may include company details, insurance, safeguarding, DBS arrangements, health and safety, risk assessments, data protection, cyber security, accessibility, contracts, references, complaints procedures and business continuity. Include only relevant material and organise it clearly.
Should all compliance documents be publicly available?
No. General policies and summaries may be published, while sensitive information such as full security reports, employee records and DBS details should be shared only where necessary through secure channels.
Do suppliers need a separate risk assessment for every school?
Not always. A core activity assessment may apply across several settings, but it must be reviewed against the specific site, participants and circumstances. Site-specific hazards or significant differences should be addressed before delivery.
Can a school supplier use subcontractors?
Yes, where the contract permits it, but the supplier should disclose relevant subcontractors and ensure they meet equivalent safeguarding, health and safety, data, insurance and quality requirements. The supplier normally remains responsible for contracted delivery.
Does framework membership make a supplier DfE approved?
Not in a universal sense. A supplier may be appointed to a particular framework or lot following a procurement process. The supplier should name that framework precisely and explain how eligible schools can use it.
How often should compliance documents be reviewed?
Review them according to legal requirements, policy dates and operational risk, and whenever services, staff, subcontractors, technology or guidance change. Insurance and certifications should be monitored by expiry date.
Who should own compliance in a small education business?
The director may retain overall responsibility, but named people should own safeguarding, health and safety, data protection, insurance and contracts according to their competence. External professional support may be necessary for specialist matters.
What is the biggest school supplier compliance mistake?
The biggest mistake is treating compliance as a folder of generic policies rather than a set of controls used in practice. Schools need evidence that the supplier’s staff understand the procedures and that those procedures match the actual service.